miguelgrinberg/python-engineio

miguelgrinberg/python-engineio

Releases144
Frequency3 weeks 6 days
Last Release
Stars257
Python Engine.IO server and client

CVE History

CVEPublishedCVSS v3CVSS v2
6.8 MEDIUM

An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, because the Origin header is not restricted.